Microsoft issues urgent security patch after ‘active attacks’ on document-sharing software

#Tech Desk
Photo: ANI
Photo: ANI

New Delhi: In a concerning development, Microsoft has released an emergency security patch following reports of "active attacks" targeting its SharePoint server software. The vulnerability affects on-premises SharePoint servers, widely used by government agencies and businesses for internal document sharing.

In a statement, Microsoft clarified that the issue does not impact SharePoint Online, the cloud-based version integrated into Microsoft 365. Only locally hosted SharePoint servers are at risk, prompting the company to urge immediate action from system administrators to apply the patch and secure their networks.

“Microsoft is aware of active attacks targeting on-premises SharePoint Server customers by exploiting vulnerabilities partially addressed by the July Security Update,” said the tech giant in its security advisory.

The company recommended security updates that customers should apply immediately.

The US Federal Bureau of Investigation (FBI) also said it is aware of the attacks and is working closely with its federal and private-sector partners.

The vulnerability is related to a case of remote code execution that arises due to the deserialization of untrusted data in on-premise versions of Microsoft SharePoint Server.

Microsoft said the current published content is correct and that the previous inconsistency does not impact the company's guidance for customers.

"After applying the latest security updates above or enabling AMSI, it is critical that customers rotate SharePoint server ASP.NET machine keys and restart IIS on all SharePoint servers," Microsoft said.

"If you cannot enable AMSI, you will need to rotate your keys after you install the new security update,” its added.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added ‘CVE-2025-53770’ vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 21, 2025.

“Microsoft has released security updates that fully protect customers using SharePoint Subscription Edition and SharePoint 2019 against the risks posed by CVE-2025-53770, and CVE-2025-53771. Customers should apply these updates immediately to ensure they’re protected,” said the company in its security update. IANS